cbcvebase.
CVE-2026-43194
published 2026-05-06

CVE-2026-43194: In the Linux kernel, the following vulnerability has been resolved: net: consume xmit errors of GSO frames udpgro_frglist.sh and udpgro_bench.sh are the…

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.53%
41.4th percentile
In the Linux kernel, the following vulnerability has been resolved: net: consume xmit errors of GSO frames udpgro_frglist.sh and udpgro_bench.sh are the flakiest tests currently in NIPA. They fail in the same exact way, TCP GRO test stalls occasionally and the test gets killed after 10min. These tests use veth to simulate GRO. They attach a trivial ("return XDP_PASS;") XDP program to the veth to force TSO off and NAPI on. Digging into the failure mode we can see that the connection is completely stuck after a burst of drops. The sender's snd_nxt is at sequence number N [1], but the receiver claims to have received (rcv_nxt) up to N + 3 * MSS [2]. Last piece of the puzzle is that senders rtx queue is not empty (let's say the block in the rtx queue is at sequence number N - 4 * MSS [3]). In this state, sender sends a retransmission from the rtx queue with a single segment, and sequence numbers N-4*MSS:N-3*MSS [3]. Receiver sees it and responds with an ACK all the way up to N + 3 * MSS [2]. But sender will reject this ack as TCP_ACK_UNSENT_DATA because it has no recollection of ever sending data that far out [1]. And we are stuck. The root cause is the mess of the xmit return codes. veth returns an error when it can't xmit a frame. We end up with a loss event like this: | GSO super frame 1 | GSO super frame 2 | |-----------------------------------------------| | seg | seg | seg | seg | seg | seg | seg | seg | | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | x ok ok | ok ok ok \\ snd_nxt "x" means packet lost by veth, and "ok" means it went thru. Since veth has TSO disabled in this test it sees individual segments. Segment 1 is on the retransmit queue and will be resent. So why did the sender not advance snd_nxt even tho it clearly did send up to seg 8? tcp_write_xmit() interprets the return code from the core to mean that data has not been sent at all. Since TCP deals with GSO super frames, not individual segment the crux of the problem is that loss of a single segment can b

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 1f59533f9ca5634e7b8914252e48aee9d9cbe501 < ae3f627b45fbc3c776a4e484696f3cad7cbb4ecaae3f627b45fbc3c776a4e484696f3cad7cbb4eca
linuxlinux>= 1f59533f9ca5634e7b8914252e48aee9d9cbe501 < 0c9de092ef8c50a7ee9612811566f0aa81d8d7b60c9de092ef8c50a7ee9612811566f0aa81d8d7b6
linuxlinux>= 1f59533f9ca5634e7b8914252e48aee9d9cbe501 < 56bd32c0edca34041a5c215887fcf562fae2e2db56bd32c0edca34041a5c215887fcf562fae2e2db
linuxlinux>= 1f59533f9ca5634e7b8914252e48aee9d9cbe501 < 9ac6aebef4b4bfc5ed408b0b65645981574bc7809ac6aebef4b4bfc5ed408b0b65645981574bc780
linuxlinux>= 1f59533f9ca5634e7b8914252e48aee9d9cbe501 < ea5d7787635e26ec1194ec7eec0e8e5ae3bd10a5ea5d7787635e26ec1194ec7eec0e8e5ae3bd10a5
linuxlinux>= 1f59533f9ca5634e7b8914252e48aee9d9cbe501 < 4cb163e9efcac4cd35c3043e097f25081a5c015c4cb163e9efcac4cd35c3043e097f25081a5c015c
linuxlinux>= 1f59533f9ca5634e7b8914252e48aee9d9cbe501 < c86901d22c89a6bf4e2f013e948aaabc60869893c86901d22c89a6bf4e2f013e948aaabc60869893
linuxlinux>= 1f59533f9ca5634e7b8914252e48aee9d9cbe501 < 7aa767d0d3d04e50ae94e770db7db8197f6669707aa767d0d3d04e50ae94e770db7db8197f666970
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 3.18 < 5.10.2525.10.252
linuxlinux_kernel>= 5.11 < 5.15.2025.15.202
linuxlinux_kernel>= 5.16 < 6.1.1656.1.165
linuxlinux_kernel>= 6.13 < 6.18.166.18.16
linuxlinux_kernel>= 6.19 < 6.19.66.19.6
linuxlinux_kernel>= 6.2 < 6.6.1286.6.128
linuxlinux_kernel>= 6.7 < 6.12.756.12.75
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-aws-fips
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu8.8HIGH
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.